Fortinet Confirms Active FortiCloud SSO Bypass on Patched Firewalls
These articles are AI-generated summaries. Please check the original sources for full details.
Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
Fortinet has confirmed continued exploitation of a FortiCloud SSO authentication bypass, despite previous patches (CVE-2025-59718 and CVE-2025-59719). The attacker is leveraging SAML abuse to bypass SSO login authentication on fully patched FortiGate devices.
Why This Matters
Ideal security models assume patches fully resolve vulnerabilities, but this incident demonstrates the persistence of real-world attack vectors. The potential impact is significant: successful exploitation allows attackers to gain administrative access, establish persistence, and exfiltrate sensitive firewall configurations, potentially compromising entire networks. The cost of remediation after a successful breach can easily exceed six figures, including incident response, data recovery, and reputational damage.
Key Insights
- CVE-2025-59718 & CVE-2025-59719: Originally addressed by Fortinet in December 2025, these vulnerabilities relate to SAML SSO authentication bypass.
- SAML Abuse: Attackers are exploiting weaknesses in the Security Assertion Markup Language (SAML) protocol to bypass authentication mechanisms.
- Persistence Tactics: Observed attacker accounts (“[email protected]”, “[email protected]”) are used to create generic accounts and establish VPN access.
Practical Applications
- Use Case: Organizations using FortiGate firewalls with FortiCloud SSO enabled are at risk of unauthorized access and configuration changes.
- Pitfall: Relying solely on patching without considering the underlying protocol vulnerabilities (like SAML) can lead to a false sense of security.
References:
Continue reading
Next article
GitHub Releases Copilot-SDK to Embed Its Agentic Runtime in Any App
Related Content
Fortinet Firewalls Hit With Malicious Configuration Changes
Compromised FortiGate devices are experiencing automated malicious SSO logins and configuration data theft.
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
Arctic Wolf reports automated attacks on FortiGate devices leveraging FortiCloud SSO vulnerabilities, resulting in unauthorized firewall changes and configuration theft.
Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login
Palo Alto Networks patched CVE-2026-0227, a critical GlobalProtect vulnerability allowing unauthenticated DoS attacks that force firewalls into maintenance mode.